---
id: CVE-2013-0248
title: >-
  The default configuration of javax.servlet.context.tempdir in Apache Commons
  FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which
  allows local users to overwrite arbitrary files via an unspecified symlink
  attack.
summary: >-
  The default configuration of javax.servlet.context.tempdir in Apache Commons
  FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which
  allows local users to overwrite arbitrary files via an unspecified symlink
  attack.
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-264
  - CWE-59
vendor: apache
product: commons_fileupload
affected:
  - commons_fileupload = 1.0
  - commons_fileupload = 1.1
  - commons_fileupload = 1.1.1
  - commons_fileupload = 1.2
  - commons_fileupload = 1.2.1
  - commons_fileupload = 1.2.2
published: '2013-03-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:08.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2013-0248'
references:
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html'
    label: secalert@redhat.com
  - url: 'http://marc.info/?l=bugtraq&m=144050155601375&w=2'
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: secalert@redhat.com
  - url: 'http://www.osvdb.org/90906'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/58326'
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: secalert@redhat.com
  - url: 'http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=144050155601375&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.osvdb.org/90906'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/58326'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:27:32.562560Z'
epss: 0.0068
epssPercentile: 0.50786
ingestedAt: '2026-10-07T19:44:15.633Z'
---

## Overview

The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.

## Affected

- `commons_fileupload = 1.0`
- `commons_fileupload = 1.1`
- `commons_fileupload = 1.1.1`
- `commons_fileupload = 1.2`
- `commons_fileupload = 1.2.1`
- `commons_fileupload = 1.2.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
